What a hijacked agent key costs under three custody models: a raw EOA key loses the whole wallet instantly, an expiry-only session key does too, and a per-period spend permission caps the bleed. Drag the sliders — or load a real 35.97 USDC/day permission pulled off Base — and watch the staircase.
Blast Radius — drag sliders to shape the permission and detection time · press ⬢ real base permission to load the on-chain example · all inputs are keyboard accessible · data as of · Base via Blockscout (tx 0xa695af07…1055) ↗
open artifact ↗
An agent holding your raw key is one prompt injection from total loss — and 97% of early EIP-7702 delegations went to drainer sweepers. We read the sweeper's source off the chain, dissect a real 35.97-USDC-a-day spend permission on Base, and do the blast-radius math.